Blue Cross & Blue Shield of Rhode Island
bd_1b41ea6d66c97050 · schema v1 · pii pii-v1
Full breach record for Blue Cross & Blue Shield of Rhode Island →Blue Cross & Blue Shield of Rhode Island reported to HHS on 2018-09-13 an Unauthorized Access/Disclosure affecting 1,567 individuals. Breached information was located on Paper/Films. Business associate RedCard, a mailing services provider, improperly consolidated Explanation of Benefits (EOB) documents, causing EOBs for different individuals at the same address to be mailed together. Exposed PHI included names, plan ID numbers, provider names, types of medical service, and claim information. The BA ceased consolidating EOBs. OCR found the BA agreement compliant with the Privacy Rule.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Sep 13, 2018
- Raw hash
- 40202e283f7d2c133756851db6d9d59b20016d5a300d68aae933166c670340ce
Source filing
Reporting entity
- Name
- Blue Cross & Blue Shield of Rhode Islandnorm: blue cross blue shield of rhode island
- Domain
- bcbsri.com
- Industry
- Insurance — Health
Victim entity
- Name
- Blue Cross & Blue Shield of Rhode Islandnorm: blue cross blue shield of rhode island
- Domain
- bcbsri.com
- Industry
- Insurance — Health
- Industry
- Healthcaresource defaultFinancial Servicesllm
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,567
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access· RedCard
- Threat actor
- Partner
- Regulator citations
- OCR reviewed the covered entity's business associate agreement with RedCard and it appeared to be in compliance with the Privacy Rule.
- Third party
- via RedCard
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.